Ennoventure is a deep-tech brand protection company that embeds invisible, cryptographic signatures directly into ordinary product packaging artwork. Using AI and cryptography, the signatures print with existing equipment - no new labels, materials, or hardware - and can be verified in about a second with an ordinary smartphone camera. Founded in 2018 by MIT Sloan alumnus Padmakumar Nair and technologist Shalini Nair, the company gives brands a scalable SaaS platform to authenticate products, detect grey-market diversion, monitor online marketplaces for counterfeits, and engage consumers, protecting global names such as Nestle and Unilever across pharma, FMCG, automotive, and more.
Lema AI is a New York-based cybersecurity startup building an agentic AI platform for third-party risk management (TPRM). Founded by three veterans of Israel's Unit 8200, Lema replaces static vendor questionnaires and check-the-box compliance with continuous, behavior-based analysis that maps how vendors actually operate inside an enterprise - tracking data access, permission changes and 'risk drift' to surface real attack paths. The company emerged from stealth in February 2026 with roughly $24M in total funding, including a $17.5M Series A led by Team8.
Nudge Security is an Austin-based cybersecurity company that helps organizations discover and govern the SaaS and AI applications their employees adopt, often without IT's knowledge. Founded in 2021 by Russell Spitler and Jaime Blasco, the platform combines Day One SaaS and AI app discovery, security posture management, identity governance, third-party risk, and spend management, then reaches employees directly with 'security nudges' via browser, Slack, and Teams to guide safer choices without blocking work. It raised a $22.5M Series A in November 2025 and serves nearly 200 customers.
Overhaul is an Austin-based supply chain risk management and visibility company that helps global shippers and logistics providers see, protect, and control high-value cargo in transit. Its device-agnostic software combines real-time monitoring, predictive risk intelligence, a 24/7 Global Security Operations Center, and insurance and recovery services to prevent theft, damage, spoilage, and compliance failures. Founded in 2016 by supply-chain-security veteran Barry Conlon, Overhaul serves Fortune 100 brands across pharmaceuticals, technology, automotive, and food and beverage, and raised a $105M Series C in August 2025.
Proof Authentication is a Boston-based technology company that builds anti-counterfeiting and brand-protection solutions for large consumer brands. Its patented approach pairs a non-duplicatable printed mark with a custom smartphone app, letting consumers verify a product's authenticity in seconds while giving brands real-time data to enforce against counterfeits. Formed in 2021 to acquire the DSS Digital division of Document Security Systems, the company is led by CEO Dan McKinnon, former Head of Global Brand Protection at New Balance, and serves Fortune 500 companies.
Eddie Dovzhik is the co-founder and CEO of Lema AI, a New York and Israel-based cybersecurity company building what it calls the world's first Agentic Risk Engineer for third-party risk management. A former Major in Israel's Unit 8200 and a former product leader at Noname Security (acquired by Akamai), Dovzhik launched Lema in 2023 with the belief that third-party risk should be treated as a security problem rather than a compliance checklist. The company emerged from stealth in early 2026 with $24 million in total funding, including a $17.5 million Series A led by Team8.
Grant Miller is the co-founder and CEO of Replicated, a platform that helps software companies ship their applications so enterprise customers can run them inside their own secure, self-managed environments. A self-taught programmer who started his career in technology M&A at Goldman Sachs, Grant first built and sold the mobile live-chat startup Look.io to LivePerson in just nine months, then set out to build a company he never wants to sell. Since founding Replicated in 2015 he has raised more than $80 million, made 'modern on-prem' a category worth taking seriously, and become a recognizable voice in enterprise software as host of the EnterpriseReady podcast.
On July 8, 2026, IBM and Red Hat announced the commercial launch of Lightwell, a platform delivering automated open source vulnerability remediation at enterprise scale. The launch, which builds on a $5 billion open source security commitment made in May 2026, introduces two offerings: Lightwell Network, a generally available catalog of 6,500+ remediated, digitally signed and certified application-layer dependencies across ecosystems like Java and Python, and Lightwell Clearinghouse Premier, a limited-availability trusted intermediary for secured patch embargoes and vertical threat coordination, starting with financial services. The initiative aims to build the 'trust infrastructure' for open source as AI accelerates both software creation and cheap, automated exploits.
Alta Resource Technologies is a Boulder, Colorado deep-tech startup using engineered proteins to selectively separate rare earth elements and other critical minerals from low-grade ores, mining tailings, and electronic waste. Its 'precision mining' platform, licensed from Lawrence Livermore National Laboratory and co-developed with Pennsylvania State University, binds individual metals with high selectivity, aiming to cut the cost and environmental damage of conventional chemical refining while helping secure a domestic U.S. supply of materials used in EVs, wind turbines, electronics, and defense systems.
Binarly is a firmware and software supply chain security company that reads the code no one else looks at - the layer below the operating system. Its AI-powered Transparency Platform analyzes firmware binaries to surface known and unknown vulnerabilities, malicious implants, misconfigurations and cryptographic weaknesses, then builds a genuine software bill of materials by reconstructing dependencies from the binary itself rather than trusting a manifest. Founded in 2021 by veteran reverse engineers Alex Matrosov and Claudiu Teodorescu, the company has disclosed hundreds of high-impact firmware vulnerabilities, including the widely covered PKfail Secure Boot flaw.
Tidal Metals is a Trenton/Hamilton, New Jersey deep-tech company that extracts primary magnesium metal from seawater and desalination brine using nothing but renewable electricity and physical processes - no ore mining, no carbon emissions, and no waste stream. Founded by three plasma-physics PhDs who met at the Princeton Plasma Physics Laboratory, the company aims to rebuild a domestic U.S. magnesium supply chain currently dominated by China, serving aerospace, defense, and next-generation automotive manufacturing.
DUST Identity authenticates physical objects with a thin coat of engineered diamond dust. Each randomly oriented constellation of microscopic diamonds forms a fingerprint that cannot be copied, and that fingerprint is bound to a tamper-evident digital record. The result is an unbroken chain of trust from raw material to final delivery, used across aerospace, defense, electronics, luxury goods, and sports memorabilia.
Obsidian Security is a Fortune 1000-focused cybersecurity company that secures business-critical SaaS applications, identities, and AI agents. Founded in 2017 by former Cylance and Carbon Black leaders, its platform unifies SaaS Security Posture Management (SSPM), Identity Threat Detection and Response (ITDR), and emerging AI agent and SaaS supply chain protection - giving enterprises visibility and control over the sprawling, interconnected SaaS ecosystems where modern breaches now begin.
Ophir Gaathon is the co-founder and CEO of DUST Identity, a Massachusetts deep-tech company that sprinkles microscopic, industrial diamond dust onto physical objects to give them an unclonable fingerprint. A Columbia-trained applied physicist who once chased the quantum properties of diamonds for computing, he turned that research into an identity layer for the physical world, used across defense, aerospace, automotive and luxury supply chains. Backed by Kleiner Perkins, Airbus Ventures, Lockheed Martin and Castle Island Ventures, his company has raised more than $50M and works on problems originally posed by DARPA.
Semgrep is a San Francisco application-security company that builds a unified AppSec platform (Code/SAST, Supply Chain/SCA, and Secrets) used by engineering teams at Dropbox, Figma, Snowflake and others. Born out of an open-source tool originally written at Facebook, it lets security teams write code-like rules and ship them through CI - cutting false positives and pushing fixes back to developers.

Russ Cox is a Distinguished Engineer at Google and the longtime technical lead of the Go programming language, the open-source language he helped shape for over a decade. Known for foundational work on RE2 (a safe, linear-time regex engine), Plan 9 from User Space, and Go's module system, he bridges deep computer science theory with production-grade engineering. After stepping down as Go tech lead in September 2024, he shifted focus to AI-powered open source tooling - building Gaby and Oscar, agent systems designed to help maintainers with the unglamorous but essential work of keeping software alive.

Sylvain Kerkour is a French software engineer, security researcher, and author best known for 'Black Hat Rust' - a hands-on book applying offensive security techniques with the Rust programming language. Self-described as a 'professional troublemaker', he writes about programming, hacking, and entrepreneurship at kerkour.com under the tagline '(Ab)using technology for fun & profit'. He is a vocal advocate for supply chain security in the Rust ecosystem and creator of the Bloom open-technology platform and the ChaCha20-BLAKE3 AEAD cipher implementation.